Lazo Lab Sign up

Web Security / Sessions and logins

Lesson 15 of 27

Storing passwords

Never store passwords in plain text, or with fast hashes like MD5. Use a slow, salted password hash such as bcrypt, scrypt or Argon2.

Key points

  • Salted and slow
  • werkzeug's generate_password_hash does this
  • Never email passwords
from werkzeug.security import generate_password_hash, check_password_hash
Watch a video on thisOpens YouTube search results for “Storing passwords” in a new tab

Quiz · +10 XP

Which is right for storing passwords?

Log in to save progress and earn XP.